VPN site to Site with the possibility to dial Back-Up

Hello

Our network currently uses a lot of Frame-Relay links, for these connections, we use the Cisco 1720 with dial back-up on analog line in case the fials Frame-Relay.

I am looking for a way to site to site VPN connection and have always the possibility to dial emergency failure of the ISP. We currently have a Cisco Pix 515E who would host connections, what would be my best option on the side of Management Office? Firewalls PIX or Cisco 1720 with modules of VPN, perhaps a combination of the two? Which would be safer?

Thank you in advance for any help you provide.

Mauro

Mauro,

Do you want to replace EN with VPN links and then save the VPN with ISDN, or keep the FR, retreating to VPN, then falling back to ISDN?

Whatever it is, the way to go is to use a dynamic routing on the EN and the VPN Protocol, so when a link fails the IP routing protocol address reconverges. This way you can always trigger the ISDN with a static route floating.

EIGRP (or any other dynamic routing protocol) to via the VPN to allow multicasting neighbourgh through a GRE tunnel.

Tags: Cisco Security

Similar Questions

  • If we have 2 remote sites with the same shared storage, can we mount a drive shared on remote site?

    Dear Experts,

    If we have 2 remote sites with the same shared storage, can mount us a drive on remote site?

    • Assume that the oracle database is on the shared disk (for example HP 3PAR)
    • Primary Oracle server with storage as a common drive (storage shared on sites geographical apart) have all the files database.
    • failure, it is possible to mount the drive even at the remote site and mount the database oracle it?

    There must be no effect on the as it should the same disk that has dismantled master site.

    Thank you and best regards,

    IVW

    Thanks a lot mseberg

    Is it a design valid ?

    • We have remote sites and want to set up DR. As we only SE pare data is therefore no choice.
    • We think of the SAN replication option.

    Have you ever seen / configured such architecture or design?

    Can you please throw some light on this. Thanks in advance for your ideas.

    Thank you best regards &,.

    IVW

  • It is a nightmare. Absolute total nightmare. Like a fool, I went to San Luis Obispo staples and bought Adobe Photoshop elements Adobe Premiere elements 14 and 14. I have logged on to your Web site with the code redemption and received your series num

    It is a nightmare. Absolute total nightmare. Like a fool, I went to San Luis Obispo staples and bought Adobe Photoshop elements Adobe Premiere elements 14 and 14. I logged on to your Web site with the redemption code and received your serial number. Of course, he did not.  Any of you have ideas.

    What is the error message?

    It is unacceptable to permit http://helpx.adobe.com/creative-suite/kb/error-serial-number-valid-product.html

  • Tabs Panel: How can I designate a default tab? The site with the tab wanted to selected download does not work for me.

    I created a tab panel and applied some styles to tabs. (Drop shadow and change the stacking order so that each tab casts a shadow on that below.) Now everytime the page loads, it will default to the lower tab. The only suggestion that I've seen is to save and load the site with the desired tab is selected and 'active'. This does not seem to solve the problem.

    Hmmm, have you looked into this widget from MuseGrid? It looks like roughly what it takes for this?

    News a new star | Adobe Muse Widget | museGrid.com

  • Can I create a slide show of slider/image carousel with the possibility for the links and the widths of the image to an Adobe program variable and then place in Muse

    Hello

    I really hope someone can help me with a project that led to drive me to despair.

    I'll put up an online art gallery, last year, I used Wix to create a site (explorersglobalfineart.com). Initially, I thought it was a good idea that I could build the mobile site with the site of the office. It turns out that features model are appalling and every time I add a new page I have to reinstall everything on the mobile site.

    In the last month, I've searched Adobe Muse. I started to build the site map and added to the artist page, but there are pages on the current site which have a slider carousel with the possibility for widths of the variable image and links that I cannot emmualte in Muse - http://www.explorersglobalfineart.com/#! Asia/cfvg

    Is there an Adobe program that I can use to create a cursor image carousel with the ability to tie and use images with varying widths which is compatible with Adobe Muse?

    Thank you very much

    Rebecca

    You can try this:

    http://musewidgets.com/products/carousel-Gallery-Widget

    Thank you

    Sanjit

  • VPN site to Site with the IP address range internal Natting?

    This is our real internal LAN address: 10.40.120.0/26 (internal range) and I want to translate to

    Translated the address: 10.254.9.64.255.255.255.192 (Internal)

    Our remote local address is: 10.254.5.64 site 255.255.255.192(Remote adresse Ip interne ajouter plage)

    Based on the above parameters I did this configuration

    outside_cryptomap ip 10.254.9.64 access list allow 255.255.255.192 10.254.5.64 255.255.255.192
    policy-nat of ip 10.40.120.0 access list allow 255.255.255.192 10.254.5.64 255.255.255.192
    public static 10.254.9.64 (inside, outside) - list of access policy-nat

    I had all the phase 1 and Phase 2 required parameters and add public ip peer.

    I had set up vpn by using ASDM before but this scenario is new for me, all I was wondering is there anything I need to properly configure Setup VPN

    If you see TX increases but not RX which means that traffic is sent to the remote end however there is no response.

    I suggest that you check with the remote end of VPN to see where is the problem. It is very probably the remote side.

  • ASA VPN Site to Site (WITH the NAT) ICMP problem

    Hi all!

    I need traffic PAT 192.168.1.0/24 (via VPN) contact remote 151.1.1.0/24, through 192.168.123.9 router in the DMZ (see diagram)

    It works with this configuration, with the exception of the ICMP.

    This is the error: Deny icmp src dmz:151.1.1.1 dst foreign entrants: 192.168.123.229 (type 0, code 0)

    Is there a way to do this?

    Thank you all!

    Marco

    ------------------------------------------------------------------------------------

    ASA Version 8.2 (2)
    !
    ciscoasa hostname
    domain default.domain.invalid
    activate 8Ry2YjIyt7RRXU24 encrypted password
    2KFQnbNIdI.2KYOU encrypted passwd
    names of
    name 192.168.1.0 network-remote control
    !
    interface Vlan1
    nameif inside
    security-level 100
    IP 192.168.200.199 255.255.255.0
    !
    interface Vlan2
    nameif outside
    security-level 0
    the IP 10.0.0.2 255.255.255.0
    !
    interface Vlan3
    prior to interface Vlan1
    nameif dmz
    security-level 0
    192.168.123.1 IP address 255.255.255.0
    !
    interface Ethernet0/0
    switchport access vlan 2
    !
    interface Ethernet0/1
    !
    interface Ethernet0/2
    !
    interface Ethernet0/3
    !
    interface Ethernet0/4
    !
    interface Ethernet0/5
    !
    interface Ethernet0/6
    !
    interface Ethernet0/7
    switchport access vlan 3
    !
    passive FTP mode
    DNS server-group DefaultDNS
    domain default.domain.invalid
    the DM_INLINE_NETWORK_1 object-group network
    object-network 151.1.1.0 255.255.255.0
    object-network 192.168.200.0 255.255.255.0
    outside_1_cryptomap list extended access allowed object-group DM_INLINE_NETWORK_1 remote ip 255.255.255.0 network
    inside_nat0_outbound to access extended list ip 192.168.200.0 allow 255.255.255.0 255.255.255.0 network-remote control
    VPN_NAT list extended access allow remote-network ip 255.255.255.0 151.1.1.0 255.255.255.0
    dmz_access_in list extended access permit icmp any one
    outside_access_in list extended access permit icmp any one
    pager lines 24
    Enable logging
    notifications of logging asdm
    Within 1500 MTU
    Outside 1500 MTU
    MTU 1500 dmz
    ICMP unreachable rate-limit 1 burst-size 1
    ICMP allow all dmz
    ASDM image disk0: / asdm - 625.bin
    don't allow no asdm history
    ARP timeout 14400
    Global 1 interface (outside)
    Global (dmz) 5 192.168.123.229
    NAT (inside) 0-list of access inside_nat0_outbound
    NAT (inside) 1 192.168.200.0 255.255.255.0
    NAT (outside) 5 VPN_NAT list of outdoor access
    Access-group outside_access_in in interface outside
    Access-group dmz_access_in in dmz interface
    Route outside 0.0.0.0 0.0.0.0 10.0.0.100 1
    Dmz route 151.1.1.0 255.255.255.0 192.168.123.9 1
    Timeout xlate 03:00
    Timeout conn 01:00 half-closed 0:10:00 udp 0:02:00 icmp 0:00:02
    Sunrpc timeout 0:10:00 h323 0:05:00 h225 mgcp from 01:00 0:05:00 mgcp-pat 0:05:00
    Sip timeout 0:30:00 sip_media 0:02:00 prompt Protocol sip-0: 03:00 sip - disconnect 0:02:00
    Timeout sip-provisional-media 0:02:00 uauth 0:05:00 absolute
    timeout tcp-proxy-reassembly 0:01:00
    dynamic-access-policy-registration DfltAccessPolicy
    Enable http server
    http 0.0.0.0 0.0.0.0 inside
    remote control-network http 255.255.255.0 inside
    No snmp server location
    No snmp Server contact
    Server enable SNMP traps snmp authentication linkup, linkdown cold start
    Crypto ipsec transform-set esp-SHA-ESP-3DES-3des esp-sha-hmac
    life crypto ipsec security association seconds 28800
    Crypto ipsec kilobytes of life - safety 4608000 association
    card crypto outside_map 1 match address outside_1_cryptomap
    card crypto outside_map 1 set pfs Group1
    card crypto outside_map 1 set peer 10.0.0.1
    card crypto outside_map 1 set of transformation-ESP-3DES-SHA
    outside_map interface card crypto outside
    crypto ISAKMP allow outside
    crypto ISAKMP policy 10
    preshared authentication
    3des encryption
    sha hash
    Group 2
    life 86400
    Telnet timeout 5
    SSH timeout 5
    Console timeout 0
    dhcpd outside auto_config
    !

    a basic threat threat detection
    Statistics-list of access threat detection
    no statistical threat detection tcp-interception
    WebVPN
    tunnel-group 10.0.0.1 type ipsec-l2l
    tunnel-group 10.0.0.1 ipsec-attributes
    pre-shared key *.
    !
    class-map inspection_default
    match default-inspection-traffic
    !
    !
    type of policy-card inspect dns preset_dns_map
    parameters
    maximum message length automatic of customer
    message-length maximum 512
    Policy-map global_policy
    class inspection_default
    inspect the preset_dns_map dns
    inspect the ftp
    inspect h323 h225
    inspect the h323 ras
    inspect the rsh
    inspect the rtsp
    inspect esmtp
    inspect sqlnet
    inspect the skinny
    inspect sunrpc
    inspect xdmcp
    inspect the sip
    inspect the netbios
    inspect the tftp
    Review the ip options
    !
    global service-policy global_policy
    context of prompt hostname
    call-home
    Profile of CiscoTAC-1
    no active account
    http https://tools.cisco.com/its/service/oddce/services/DDCEService destination address
    email address of destination [email protected] / * /
    destination-mode http transport
    Subscribe to alert-group diagnosis
    Subscribe to alert-group environment
    Subscribe to alert-group monthly periodic inventory
    monthly periodicals to subscribe to alert-group configuration
    daily periodic subscribe to alert-group telemetry
    ------------------------------------------------------------------------------------

    Review the link, you have two ways to leave outgoing icmp, good acl or icmp inspection

    http://www.Cisco.com/en/us/products/HW/vpndevc/ps2030/products_tech_note09186a0080094e8a.shtml

  • Site to Site with the subnets overlap

    Hi all

    Search for comfirmation on what is / is not possible. In short, we have a requirement of site but our local LAN varies from conflict. I am aware of how this get up and running with the help of a pool of IP addresses that is a basic ASA/IOS device can NAT behind but I wonder if it is possible to NAT behind a single IP address. NAT is also in place for the general internet traffic, but I hope that the image attached best describes our scenario.

    Any help / advice appreciated.

    Kind regards

    Martyn

    Hello

    You will need to do NAT on both ends to get the installation work.

    With these types of configurations, I more often just a 24 natted network to 24 another network on both sites.

    You can configure one of the sites use a PAT address towards the other end, but the other end must have protected by some sort of NAT static between the hosts unique or equal to 24 networks.

    If you would happen to configure both sites with a PAT translation, you couldn't really initiate connections between the site because no real host on networks 192.168.1.0/24 would have their own specific NAT IP to connect to.

    So in short

    • Both sites need NAT network
    • Use 1:1 NAT static is between host addresses or complete networks on both sites
      • The two sites could start the connection to any host on the remote end every single host has its own IP NAT staticly assigned address
    • Use of PAT for site and other NAT static 1:1 with the addresses of host or complete networks on the other site
      • Site with unique PAT IP address can connect to all hosts of remote sites, since they have staticly NAT IP addresses assigned.
      • Homepage is not able to connect to any host at his remote site that the remote site has only a PAT address facing their way.

    If you had 2 ASAs with 8.2 or UNDER software your static NAT configurations could be e.g.

    Basic information

    • Site1: 192.168.1.0/24
    • Site1 NAT: 10.10.1.0/24
    • Site2: 192.168.1.0/24
    • Site2 NAT: 10.10.2.0/24

    Static configuration NAT of policy site1

    permit L2L-VPN-POLICYNAT from the list of access ip 192.168.1.0 255.255.255.0 10.10.2.0 255.255.255.0

    public static (inside, outside) 10.10.1.0 - L2L-VPN-POLICYNAT access list

    Static configuration NAT of policy site2

    permit L2L-VPN-POLICYNAT from the list of access ip 192.168.1.0 255.255.255.0 10.10.1.0 255.255.255.0

    public static (inside, outside) 10.10.2.0 - L2L-VPN-POLICYNAT access list

    PAT configuration at each end

    permit L2L-VPN-POLICYPAT from the list of access ip 192.168.1.0 255.255.255.0 10.10.x.0 255.255.255.0

    Global 10.10.x.1 of xxx (outside)

    NAT (inside) xxx access-list L2L-VPN-POLICYPAT

    If you had 2 ASAs with 8.3 or above software your static NAT configurations could be for example (same information base)

    Static configuration NAT of policy site1

    the object of the LAN network

    subnet 192.168.1.0 255.255.255.0

    network of the LAN - NAT object

    10.10.1.0 subnet 255.255.255.0

    network of the REMOTE object

    255.255.255.0 subnet 10.10.2.0

    static (inside, outside) 1 static source LAN LAN - NAT static destination REMOTE

    Static configuration NAT of policy site2

    the object of the LAN network

    subnet 192.168.1.0 255.255.255.0

    network of the LAN - NAT object

    255.255.255.0 subnet 10.10.2.0

    network of the REMOTE object

    10.10.1.0 subnet 255.255.255.0

    static (inside, outside) 1 static source LAN LAN - NAT static destination REMOTE

    PAT configuration at each end

    the object of the LAN network

    subnet 192.168.1.0 255.255.255.0

    network of the LAN-PAT object

    Home 10.10.x.1

    network of the REMOTE object

    10.10.x.0 subnet 255.255.255.0

    static (inside, outside) 1 dynamic source LAN LAN-PAT destination static REMOTE

    -Jouni

  • System crashes, moreover, it freezes during playback of the media or on a site with the media.

    If I go on a site with video, it stops, and a sound is heard.  It crashes sometimes.  These are the messages I had

    Stop: OxOOOOO8E (Ox805BC1E9, OxBA287c7c, OxcOOOOOO5, OXOOOOOOOO)

    ALSO

    BCCode: 1000008e BCP1: C0000005 BCP2: 805BC1E9 BCP3: BA287C7C
    BCP4: 00000000 OSVer: 5_1_2600 SP: 3_0 product: 256_1

    Please provide additional information on your system:
    What is your system brand and model?
    What is your version of XP and the Service Pack?
    Describe your current antivirus and software anti malware situation: McAfee, Norton, Spybot, AVG, Avira
    !, Defender, ZoneAlarm, PC Tools, MSE, Comodo, etc..
    Click Start, run and enter in the box:
    Msinfo32
    Click on OK and when the system info summary appears, click on Edition, select all, copy, and then paste the information here.
    For information about video drivers, expand components, click view, click on edit, select all, copy and then paste the information here.
    For more audio information, expand components, click on Sound Device, click on edit, select all, copy and then paste the information here.
    There will be some personal information (such as the user name and the name of the system), and anything that turns information private for you, simply delete the pasted information.
    This will minimize back Q & A and eliminate guesswork.
    Download BlueScreenView here:
    Unzip it and run it (BSV installs nothing) and let him complete the digitization of all of your files to dump.
    If you double-click on depressed, you will get information on it (including the field caused by the driver) and you should be able to spot the problem right away - especially if you see a model in landfills where Caused by field pilot is the same (beginning with this driver).
    Select (highlight) one or more of the most recent dump files by clicking on them and hold down the CTRL key to select multiple files.  Try to select only the most recent links that relate to your problem (perhaps five or six to start dump files).
    Click on file, save selected items and save information from the dumps to a text file on your desktop called BSOD.txt.  Open BSOD.txt with a text editor, copy the text and paste it in your next reply.
    Here's an example of report ASB to a single BSOD I initiated on purpose that indicates the cause of the accident as the pilot i8042prt.sys belonging to Microsoft Corporation:
    ==================================================
    Dump file: Mini062110 - 01.dmp
    Crash time: 21/06/2010-11:51:31
    Bug Check String: MANUALLY_INITIATED_CRASH
    Bug check code: 0x000000e2
    Parameter 1: 0x00000000
    Parameter 2: 0x00000000
    Parameter 3: 0x00000000
    Parameter 4: 0x00000000
    Caused by the driver: i8042prt.sys
    Caused by the address: i8042prt.sys + 27fb
    Description of the file: i8042 Port driver
    Product name: Microsoft® Windows® Operating System
    Company: Microsoft Corporation
    File version: 5.1.2600.5512 (xpsp.080413 - 2108)
    Processor: 32-bit
    Computer name:
    Full path: C:\WINDOWS\minidump\Mini062110-01.dmp
    ==================================================
    Send information from 5 last memory dumps.
    No matter what you use for protection against malware, please follow these steps:
    Download, install, update and do a full scan with these free malware detection programs:
    Malwarebytes (MMFA): http://malwarebytes.org/
    SUPERAntiSpyware: (SAS): http://www.superantispyware.com/
    It can be uninstalled later if you wish.

    Do not guess what the problem might be - understand and resolve it. I need YOUR voice and the points for helpful answers and propose responses. I'm saving for a pony!

  • A web site with the IIS configuration network location

    Is there information on how to set up a web site to a network location.  I have a shared directory of Mac that I have access to my Windows Vista pc.  I have a Server IIS Web on this PC and want to test the Mac files with the IIS Web server on the Windows computer.  I created a site in IIS and pointed on the shared drive, this resulted in an error: cannot read the web.config configuration file.  I tried a different approach: create a local site to wwwroot, then create a virtual directory.  This brought the same error: the requested page cannot be accessed because the configuration data of the page are invalid.  I have IIS 7 on Windows Vista Business Edition.

    Hello

    Your question of Windows Vista is more complex than what is generally answered in the Microsoft Answers forums. It is better suited for the public on the forums of IIS. Please post your question in the following link for assistance:

    Link to the forum:

    http://forums.IIS.NET/1047.aspx

  • How to implement multi-site with the same URL field in the ATG

    Hi guys,.

    I have a multisite transposition obligation with the same url domain but ATG does not support same domain URL for multisite. Can someone please help me with this problem?

    David.De - Oracle

    Thank you

    Vivek

    As I said use custom filters to read the parameter when the user clicks on the link for the site of CA and set the site context.

    You can store a cookie that determines the site for subsequent applications.

    Peace

    Shaik

  • How can I download the new update on my Macbook pro when the password is not working? When I connect to the Adobe site with the same user name and password it DOES not work. I don't understand why.

    So I have a macbook pro - and she advised me that I had to update my Adobe flash player. So I go through all the steps and I'm stuck at the last stage, where he asks me my user name and password. I go in there correctly - several times and it does NOT connect. He shakes to show that there's an error. Double check my file AND I go to the Adobe site to connect with the same information. and it works very well.

    WHAT IS THE PROBLEM? Help please.

    Could you please try ComputerName administrator as username and the password as password.

    I hope this works.

    Concerning

    Hervé Khare

  • Receive the error message to the Web site of the possible malware attack

    which is: http://374cfb3.f1c5.net/vguard/?fe6c4b=wggwbl&a2987=mmlhahahwx&4cd=mlgwmqfwgx&6=2

    I get this error message:

    http://374cfb3.f1c5.NET/VGUARD/?fe6c4b=wggwbl&A2987=mmlhahahwx&4CD=mlgwmqfwgx&6=2

    My scan said I have no problem, but I get this warning and I'm closed down you know why?

    It started when I bought AVG Security.

    It is always sensible in this situation to achieve a malware check

    Download and install Malwarebytes (free version for individuals only), updated definitions and run in safe mode. Disable other security software while you do the analyses.

    http://www.Malwarebytes.org/

    Download and run SuperAntiSpyware (Free Edition)

    http://www.SUPERAntiSpyware.com/download.html

    Your problem might be an orphan entry caused by the incomplete elimination of malware.

    To identify what loads when you start using Autoruns (freeware from Microsoft).

    http://www.Microsoft.com/technet/sysinternals/ProcessesAndThreads/Autoruns.mspx

    With Autoruns, you can deselect an item which disables startup, or you can click with the right button on an item, then remove it. If you clear the check box that you can check back for re - activate the element. It is an approach much safer than editing the registry and better than using msconfig.

    Another useful feature of the program is that you can click with the right button on an item and select search online to get information about the selected item.

  • 2 VPN to separate networks with the same intellectual property regime

    We have an office in Bermuda and 2 offices in Chicago. 2 offices in Chicago have the same pattern of IP - 10.150.1.0/24. I would like to set up a VPN site-to site of Bermuda for each of the offices of Chicago. I have one up and it works fine. When I set up the 2nd, I can pass in Chicago, but not receive. I guess it has to do with the same IP networks. Is there a way around this problem?

    Thank you

    Scott

    Yes you need to nat all traffic goes to one of the sights of Chicago. This way others will see it as a completely different subnet. It is a guide of cisco.com:

    http://www.Cisco.com/en/us/products/HW/vpndevc/ps2030/products_configuration_example09186a00808c9950.shtml

  • Validation with the possibility of warning?

    Hello

    I have a page with the validation of the order of the day and a button.
    When they press save button I would as validations normally (by ensuring that they have entered good data).
    Then, I want to check to see if a line with certain characteristics already exists in the table and cases in it, use a popup to warn users. They can click to continue the save or cancel the registration. If they choose to continue, the process associated with this key page runs. If they indicate to cancel all the stops treatment.

    Is it possible with a page-level validation to set up a confirm message?
    If this isn't the case, any suggestions for a solution would be appreciated.

    Thank you

    Hi Nann,

    One way to do this would be...

    Suppose your form as the page1 page.

    1 > create new page, tell page 2 and pass all DML processes in page1 page2.
    2 > Create hidden point on page1, say P1_FOUND
    3 > create a new process of PL/SQL page (after submit) in page1 do the following.

    -check for a line with certain features already exist in the table
    -If exists, then assign P1_FOUND to YES to no.
    4 > create an item hidden on page 2, say P2_FOUND and set the source used to "always replace the value that exists in the session state.
    5 > page 1, create submit after branch, which caters to the page2. Here you define the 'P2_FOUND' element with '& P1_FOUND.'
    6 > on page 2, page footer, put the following code JS

    
    

    7 > ensure that processes page2 are conditional so that they only run when ASK = 'PROCESS '.
    8 > in page2, create submit after page branching that targets go back to page 1.

    It could be that useful :-)

    See you soon
    Hari

Maybe you are looking for